CVE
- Id
- 3335
- CVE No.
- CVE-2001-0521
- Status
- Candidate
- Description
- Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.
- Phase
- Proposed (20010727)
- Votes
- ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese | REVIEWING(1) Bishop
- Comments
- CHANGE> [Frech changed vote from ACCEPT to MODIFY] | Frech> DELREF:XF:esafe-gateway-bypass-filtering(6580) | ADDREF:XF:content-unicode-bypass-filter(6980) | Baker> Found acknowledgement in the release notes for build 71, that said: | | "15. Fixed a bug that used to cause the SmartStripping mechanism to miss some scripts in HTML pages." | | Release notes are at the following url: | ftp://ftp.ealaddin.com/pub/manuals/ESG/ESG3.x/esg_rn.zip